Description
goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the authenticated proxy without providing credentials, enabling arbitrary TCP traffic relay and access to restricted destinations.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass via CONNECT
Action: Patch
AI Analysis

Impact

goproxy, a Go-based HTTP proxy, does not apply basic authentication when handling CONNECT tunnel requests. This flaw lets an unauthenticated client open a tunnel through the proxy as if credentials had been supplied, enabling the relay of arbitrary TCP traffic. As a result, an attacker can reach internal or otherwise protected destinations by simply sending CONNECT requests, undermining the authentication model of the proxy.

Affected Systems

The vulnerable product is GoProxy from the snail007 project. Versions up to and including v15.3 do not enforce authentication on CONNECT requests, making them susceptible to attack. Any deployment of these versions that is exposed to untrusted network traffic is at risk.

Risk and Exploitability

The CVSS score of 6.9 EPSS score of <1% indicates that exploitation is currently considered low probability, and the vulnerability is not listed in CISA's KEV catalog. Nevertheless, the flaw can be exploited by any remote client that can reach the proxy by sending a CONNECT request. No special privileges are required, and the attack is performed solely over standard network connections, making it a practical threat for attackers who target exposed proxy services.

Generated by OpenCVE AI on September 17, 2026 at 19:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GoProxy to version 15.4 or later to enforce authentication on CONNECT requests.
  • If an upgrade cannot be performed immediately, configure the proxy or use a reverse proxy to disable or restrict the CONNECT method, effectively blocking unauthenticated tunneling.
  • Apply network‑level controls—such as IP whitelisting or VPN enforcement—to limit which clients are allowed to send CONNECT requests to the proxy.

Generated by OpenCVE AI on September 17, 2026 at 19:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Snail007
Snail007 goproxy
Vendors & Products Snail007
Snail007 goproxy

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the authenticated proxy without providing credentials, enabling arbitrary TCP traffic relay and access to restricted destinations.
Title goproxy through 15.3 Authentication Bypass via CONNECT
First Time appeared Goproxy Project
Goproxy Project goproxy
Weaknesses CWE-288
CPEs cpe:2.3:a:goproxy_project:goproxy:*:*:*:*:*:*:*:*
Vendors & Products Goproxy Project
Goproxy Project goproxy
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Goproxy Project Goproxy
Snail007 Goproxy
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:10.409Z

Reserved: 2026-09-14T20:35:39.074Z

Link: CVE-2026-91143

cve-icon Vulnrichment

Updated: 2026-09-15T19:12:10.259Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T22:16:58.880

Modified: 2026-09-23T17:17:47.747

Link: CVE-2026-91143

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel